—
RUSTSEC-2026-0113
`unpack_in` can chmod arbitrary directories by following symlinks
Details
In versions 0.6.0 and earlier of astral-tokio-tar, the unpack_in API could inadvertently modify the permissions of external (i.e. non-archive) directories outside of the archive. An attacker could use this to contrite a tar archive that maliciously changes directory permissions outside of its intended hierarchy. This flaw only affects directories; individual file permissions cannot be modified via it.
See GHSA-j4xf-2g29-59ph for the equivalent flaw in the tar crate.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/astral-tokio-tar
Introduced in:
0.0.0-0Fixed in: 0.6.1Upgrade astral-tokio-tar to 0.6.1 or newer (ecosystem crates.io).